Data processing agreement
Last updated: 3 September 2026
When people answer your link, you decide what is asked and why — so you are the controller of those answers and we process them for you. This sets out the terms of that, and forms part of the agreement between you and Galaxy Labs Limited (registered in New Zealand, company number 9439298).
Which data this covers
Everything collected through a link you made: the random visitor identifier, the two-letter country, the times the link was opened, the answers chosen, and any written text or email address you asked for.
It does not cover your own account details. We are the controller of those, and the privacy policy governs them.
Who does what
You are the controller. You choose the questions, so you decide what is collected and why, and you are responsible for having a lawful basis and for telling your audience what you are doing.
We are the processor. We act on your documented instructions — which, in practice, are the settings you choose and the questions you write — and for no other purpose. We do not sell it, mine it, or use it to train anything.
What we do with it
- Store it, so your results survive between visits.
- Count it, so the map and totals can be drawn.
- Show it to whoever opens your link, but only the aggregate, and only while you have results set to public. Written answers are never shown to them.
- Show all of it to you, in your dashboard.
Sub-processors
- Supabase — the database it is stored in.
- Vercel — hosting, and the edge that turns a network address into a country.
- Clerk — accounts, which touches your details rather than your audience's.
Each is bound by terms no weaker than these. If we add or replace one we will update this page and the date on it before the change takes effect; if you object, you may close your account and take your data with you.
Security
- Everything travels over TLS and is encrypted at rest by our database provider.
- The database refuses all access by default; only our server-side code can read or write, and no key capable of it is ever sent to a browser.
- An audience is never asked to sign in, so there are no audience credentials to lose.
- Access to production is limited to people who need it.
Data minimisation, by construction
The service is built to collect little. An audience contributes presence and a choice from a list you wrote — no name, no account, and no IP address stored. Country is two letters and is derived rather than kept.
Where you do ask for more, by adding a written or email question, that is your choice as controller and your responsibility to justify.
International transfers
Our providers operate infrastructure in several countries, so data may be processed outside New Zealand and outside the region your audience is in. Where the GDPR applies, transfers rely on the European Commission's Standard Contractual Clauses or an adequacy decision.
Requests from your audience
If somebody asks us for access to, or deletion of, an answer they gave you, we will not act on it ourselves — we will pass it to you and help you respond, because the decision is yours. If you ask us to delete it, we will.
Breaches
If we learn of a breach affecting data we process for you, we will tell you without undue delay and, in any case, within 72 hours of becoming aware — with what we know, what we are doing, and what you may need to do.
Deletion and return
Delete a link and it stops collecting immediately. Ask us to erase what it gathered and we will, within 30 days, except where we are required to keep something by law.
On request we will give you what we hold for you in a machine-readable form. If your account ends, the same applies for 30 days afterwards.
Audit
On reasonable notice, and no more than once a year unless a regulator requires otherwise, we will answer written questions about our handling of your data and provide what we have to demonstrate compliance.
Contact
Data-protection questions and requests under this agreement go to contact@mappbook.com.
